Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2024-55926: Xerox Workplace Suite allows unauthorized file access and deletion
CVE-2024-55926 · published 1 year ago
Summary
A security flaw in Xerox Workplace Suite can be exploited to access, upload, and delete sensitive files on the server. This can lead to unauthorized access to confidential data. Update the software to the latest version to fix the issue.
What to do
- Update xerox workplace_suite to version 5.6.701.9 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| xerox | workplace_suite |
< 5.6.701.9 cpe:2.3:a:xerox:workplace_suite:*:*:*:*:*:*:*:* |
Original advisory text
A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through crafted header manipulation. By exploiting improper validation of headers, atta...
A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through crafted header manipulation. By exploiting improper validation of headers, attackers can gain unauthorized access to data
References
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-22Path Traversal
CWE-434Unrestricted File Upload
Timeline
Published23 Jan 2025
Updated18 Aug 2026
First seen6 Mar 2026
Sources
CVE-2024-55926 · NVD
Monitor software like this
Free during beta